Offensive Security Analyst

3 weeks ago


Malvern, United States Vanguard Full time
We are seeking an Offensive Security Analyst with advanced expertise in web application penetration testing to join our team. In this role, you will be responsible for identifying and exploiting security vulnerabilities within web applications, APIs, and cloud environments, helping to protect our organization's assets from sophisticated cyber threats. As a key member of the offensive security team, you will conduct red team operations, simulate attacks, and collaborate with cross-functional teams to improve security posture and mitigate risks. This position demands hands-on experience, technical proficiency, and a strong understanding of the latest vulnerabilities, attack techniques, and exploitation methods.

Global Risk and Security (GR&S) at Vanguard enables business strategy, protects client and Vanguard interests (e.g., assets and data), and stewards a strong risk culture. Our teams leverage enterprise-wide insights, deep expertise, and trusted advice so that across Vanguard leaders and crew drive faster, stronger, risk-informed decisions.

We are seeking an Offensive Security Analyst with advanced expertise in web application penetration testing to join our team. In this role, you will be responsible for identifying and exploiting security vulnerabilities within web applications, APIs, and cloud environments, helping to protect our organization's assets from sophisticated cyber threats. As a key member of the offensive security team, you will conduct red team operations, simulate attacks, and collaborate with cross-functional teams to improve security posture and mitigate risks. This position demands hands-on experience, technical proficiency, and a strong understanding of the latest vulnerabilities, attack techniques, and exploitation methods.

Responsibilities:

  • Perform comprehensive web application penetration testing and vulnerability assessments across internal and external web applications.
  • Identify, exploit, and document security vulnerabilities in web applications, APIs, and cloud environments, providing detailed risk assessments and recommendations for remediation.
  • Simulate real-world attacks to evaluate application security controls and detect potential threats.
  • Collaborate with development and security teams to offer actionable guidance on fixing vulnerabilities and strengthening security posture.
  • Prepare detailed penetration testing reports and clearly communicate findings to technical and non-technical stakeholders.
  • Continuously research and stay current on emerging vulnerabilities, security trends, and attack vectors in the web application landscape.
  • Assist in security incident response by identifying and analyzing vulnerabilities that may be exploited during an attack.
  • Conduct threat modeling and provide input on security requirements for application development.
  • Develop and maintain custom scripts and tools to enhance penetration testing efforts.
  • Mentor junior security team members and contribute to the overall knowledge base of the security team.

Qualifications:

  • Proven experience in web application penetration testing, with a strong background in identifying vulnerabilities, performing manual testing, and using automated tools.
  • Deep understanding of web application security concepts, including OWASP Top 10, secure coding practices, authentication and authorization mechanisms, session management, and input validation.
  • Proficiency in using security tools such as Burp Suite, OWASP ZAP, Metasploit, and other custom scripts for penetration testing.
  • Strong knowledge of web technologies such as HTML, JavaScript, CSS, AJAX, and HTTP/HTTPS protocols.
  • Hands-on experience with exploiting common web vulnerabilities like SQL injection, XSS, CSRF, SSRF, RCE, XXE, and IDOR.
  • Familiarity with security testing methodologies, frameworks, and standards (e.g., OWASP, PTES, NIST, MITRE ATT&CK).
  • Strong scripting and programming skills (e.g., Python, JavaScript, Bash, PowerShell) to develop custom exploits and automate tasks.
  • Strong analytical and problem-solving skills, with the ability to think like an attacker and identify creative ways to exploit vulnerabilities.

Preferred Certifications:

  • Offensive Security Certified Professional (OSCP)
  • Offensive Security Web Assessor (OSWA)
  • Offensive Security Web Expert (OSWE)
  • GIAC Web Application Penetration Tester (GWAPT)

Additional Skills (Preferred but not Required):

  • Experience with cloud environments (AWS, Azure, GCP) and their security models.
  • Familiarity with DevSecOps practices and integrating security into CI/CD pipelines.
  • Knowledge of cryptography, secure communication protocols, and encryption standards.
  • Experience in red teaming or advanced adversary emulation.

Special Factors

Sponsorship

Vanguard is not offering visa sponsorship for this position.

About Vanguard

At Vanguard, we don't just have a mission—we're on a mission.

To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.

Our commitment to diversity, equity, and inclusion

Vanguard’s commitment to diversity, equity, and inclusion (DEI) is central to our ability to deliver on our mission. We aspire to create a work environment that is inclusive, equitable, and diverse—one that enables our employees, whom we call crew, to thrive and bring their best selves to work every day on behalf of our clients.

Cultivating DEI lifts our entire organization, and everyone shares accountability for our progress—from our senior leaders who lay the foundation and set the example for inclusive behaviors to crew who are growing in their personal DEI learning experiences.

Together, we’re on a mission. We are fueled by the value of diverse voices and connected through friendships and a culture of care—for our clients, our communities, and each other.    

Vanguard’s DEI journey has no finish line. Our commitment is enduring, and we remain focused on the path ahead. To learn more about Vanguard goals and progress toward DEI, download our Diversity, Equity, and Inclusion Report.

How We Work

Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.



  • Malvern, Pennsylvania, United States Vanguard Full time

    Job Title: Offensive Security AnalystWe are seeking a highly skilled Offensive Security Analyst to join our team at Vanguard. As a key member of our offensive security team, you will be responsible for identifying and exploiting security vulnerabilities within web applications, APIs, and cloud environments, helping to protect our organization's assets from...


  • Malvern, Arkansas, United States Vanguard Full time

    We are seeking a skilled Offensive Security Analyst to join our team at Vanguard. This role involves identifying and exploiting security vulnerabilities within web applications, APIs, and cloud environments to protect our organization's assets from sophisticated cyber threats.Responsibilities:Perform comprehensive web application penetration testing and...


  • Malvern, Iowa, United States Endo International Full time

    About the Role:The Sr IT Security Analyst will be responsible for designing, implementing, and maintaining controls and IT Security practices/procedures to protect company assets.Key responsibilities include advising senior management on critical security issues, recommending risk-reduction solutions, and escalating complex and high-priority incidents to...


  • Malvern, United States Endo International Full time

    Why Endo? We want the best and brightest people at Endo to help us achieve our mission to develop and deliver life-enhancing products through focused execution. Our nearly 3,000 global team members understand the important role we play in delivering healthcare and are dedicated to supporting each other as we work to bring the best treatments forward. Our...


  • Malvern, Pennsylvania, United States Endo International Full time

    Why Endo?We strive to create a workplace where our employees feel valued, respected, and empowered. Our commitment to equal employment opportunity extends to every aspect of employment, including recruitment, hiring, training, promotions, compensation, benefits, transfers, terminations, and all other employment practices.We believe in the principles of equal...


  • Malvern, United States Endo Full time

    Why Endo?We want the best and brightest people at Endo to help us achieve our mission to develop and deliver life-enhancing products through focused execution. Our nearly 3,000 global team members understand the important role we play in delivering healthcare and are dedicated to supporting each other as we work to bring the best treatments forward. Our...


  • Malvern, Arkansas, United States Saxon Global Full time

    Job SummaryThis is a 12-month contract with Vanguard, 100% remote. All visa types are accepted, except H1B. Only EST candidates are preferred. Local candidates in PA are highly recommended. A LinkedIn profile is required.Key ResponsibilitiesPerform network and endpoint threat hunting, creating and maintaining SIEM correlation rules, reports, and...


  • Malvern, Iowa, United States Saint-Gobain High Performance Solutions - Life Sciences, Composites & Mobility Full time

    Job Title: Data Analyst SupervisorWe are seeking a highly skilled Data Analyst Supervisor to join our team at Saint-Gobain High Performance Solutions - Life Sciences, Composites & Mobility. As a Data Analyst Supervisor, you will be responsible for ensuring the accuracy and timeliness of master data processing within our Gypsum US&CA and Ceilings business...


  • Malvern, United States Planet Technology Full time

    Location : Malvern PA -Hybrid - 3/days onsiteDuration : 12 months plusopen for C2CThe candidate will be working on the Equity Trade floor providing production support for our portfolio management and trading crew, capital markets, security lending, data (benchmark and security reference) and Investment book of records teams. Supported applications are a mix...

  • Support Analyst

    7 days ago


    Malvern, United States Tata Consultancy Services Full time

    Job Title MS Dynamics CRM 365- Senior Support AnalystRelevant Experience (in Yrs) 6+ Years of Dynamics CRM with total 10+ years of experienceTechnical/Functional Skills Experience: 6+ years of experience working with many modules within Microsoft Dynamics 365Technical Skills: Proven experience with D365 configuration, customization, and integration Support;...


  • Malvern, PA, United States Endo Full time

    Why Endo?We want the best and brightest people at Endo to help us achieve our mission to develop and deliver life-enhancing products through focused execution. Our nearly 3,000 global team members understand the important role we play in delivering healthcare and are dedicated to supporting each other as we work to bring the best treatments forward. Our...

  • Master Data Analyst

    4 weeks ago


    Malvern, Arkansas, United States Saint-Gobain Full time

    Job SummaryThis role supports shared services activities for internal customers of the Shared Service Center (SSC) as governed by the customer Master Service Agreement (MSA) and Statement of Work (SOW).The Master Data Analyst will serve as the primary point of contact for several business units who are internal customers of the SSC, driving continuous...


  • Malvern, Arkansas, United States Saxon Global Full time

    Job SummaryAs an IAM Provisioning Analyst, you will be responsible for providing administrative access to technology platforms, performing workstation administration, and executing privileged commands. You will also be responsible for completing access security requests, analyzing security impact, and maintaining effective service relationships with business...


  • Malvern, United States Saint-Gobain North America Full time

    WHY DO WE NEED YOU ?The objective of the Digital Transformation department is to leverage digital technology and tools to accelerate the empowerment of our finance teams to become the best in class. Accelerating the adoption of digital tools will help finance teams simplify reporting processes, allow them to leverage the vast quantities of data, but also...


  • Malvern, United States Customers Bank Full time

    Malvern, PA Full time REQ-2024-521 At Customers Bank, we believe in working hard, working smart, working together to deliver memorable customer experiences and having fun. Our vision, mission, and values guide us along our path to achieve excellence. Passion, attitude, creativity, integrity, alignment, and execution are cornerstones of our behaviors. They...


  • Malvern, Iowa, United States Customers Bank Full time

    Job Title: Salesforce Programmer / AnalystJob Summary:We are seeking a skilled Salesforce Programmer / Analyst to join our team at Customers Bank. As a Salesforce Programmer / Analyst, you will be responsible for designing, developing, and deploying customized solutions within the Salesforce and nCino platforms to enhance our banking operations.Key...

  • Mainframe Developer

    4 weeks ago


    Malvern, Arkansas, United States Saxon Global Full time

    Job Summary:This is a 12-month contract position with Saxon Global. The successful candidate will work on-site in Malvern, PA or Dallas, TX for 3 days and remotely for 2 days. The role requires a strong background in Mainframe, Cobol, and DB2.Key Responsibilities:Provide system analysis, design, development, and implementation of data services for Web-based...


  • Malvern, United States United Parcel Service Full time

    SHIFT YOUR FUTURE Seasonal Support Driver SHIFT YOUR TEAM Who exactly are UPS Seasonal Support Drivers? As a Seasonal Support Driver you’ll deliver packages throughout their communities, connecting with customers along the way while driving their own vehicle. This is a friendly, physically active crew who enjoy fast-paced work, being outdoors,...


  • Malvern, Pennsylvania, United States Vanguard Group Full time

    Global Risk and Security at VanguardThe Fixed Income Investment Risk Analyst role is a critical component of our risk management infrastructure. This position will provide investment risk management expertise and analysis across fixed income funds in a global environment.The successful candidate will develop, implement, and maintain an effective and...


  • Malvern, United States ORS Partners Full time

    OverviewRemote or Hybrid to Wayne, PA The DevOps Engineer/Team Lead works with various areas of the business to collaborate on an infrastructure strategy that is secure, scalable, high performance and aligned with the goal of continuous integration and continuous deployment. Additionally, this team member is responsible for helping build the standards for...